Skip to content

Approaching: Nov 20, 2026 — HCS 2024 Deadline. Get ready →

API, webhooks, and an export that gives everything back

Read the full API reference before you talk to anyone. No account, no demo booking, no sales call, and no upgrade. If a compliance platform cannot show you how to get your own data out, that is the answer to your question.

Six read endpoints, scoped to your organization

Every request carries a token you create yourself from Settings. A token is scoped: it opens only the resources you ticked, and only your organization's data. The secret is shown once, at creation. We store a SHA-256 fingerprint, so we cannot show it to you again, and neither can anyone who reaches our database.

  • GET /v1/chemicals

    Chemical inventory: product, manufacturer, CAS number, signal word, GHS symbols, hazard statements.

  • GET /v1/jobsites

    Jobsites: name, job number, address, NAICS code, active flag.

  • GET /v1/incidents

    OSHA incident records, de-identified: case number, date, injury category, jobsite.

  • GET /v1/trainings

    Training records: course, completion date, expiration date, status.

  • GET /v1/permits

    Hot work, confined space and excavation permits under one shape.

  • GET /v1/actions

    Corrective actions: title, source, priority, due date, status.

Injury records come back de-identified. Case number, date, injury category and jobsite travel; names and dates of birth do not. A reporting pipeline is not a reason to hand out the identity of an injured worker.

Signed webhooks on five compliance events

Register an HTTPS endpoint and we post to it when one of these happens. Each request carries an HMAC-SHA256 signature computed over the timestamp and the body, so your receiver can prove the call came from us. Replaying the same event does not create a second delivery, and every attempt is written to a log you can read.

  • sds.expiringA safety data sheet is approaching or past its review date.
  • incident.createdA near miss or incident was reported.
  • action.overdueA corrective action reached or passed its due date.
  • permit.expiringA work permit is expiring or has expired.
  • training.assignedA training was assigned to a worker.

One button, everything back

From Settings, Download everything produces a single archive: your records as structured data, your safety data sheets and signed documents as files, and a manifest listing what came out. It runs on demand, without a support ticket and without a professional services quote.

This matters more than it sounds. OSHA's retention duties name the employer and never the software vendor: 29 CFR 1904.33(a) says you must save the OSHA 300 Log, the annual summary and the 301 forms for five years after the calendar year they cover, and 29 CFR 1910.1020(d) says each employer shall preserve employee exposure records for at least thirty years, and medical records for the duration of employment plus thirty. If your records are stuck in a system you no longer have, the citation is still written to you. We wrote up what that means when you change systems in which OSHA records must come with you.

Included in every plan

The API, the webhooks and the export are part of every subscription, from the entry plan up. There is no integration tier, no API add-on, and no upgrade prompt standing between you and your own data. Nothing about how your records are secured depends on what you pay.

Public reference data, no key needed

The OSHA reference data this site's pages are built from is also published as JSON and plain text. No token, no sign-up, and the JSON endpoints answer any origin. Responses are cached for up to a day.

Check it yourself

Open the reference, read the authentication section, and see what a response looks like before you create an account.

Writing about OSHA compliance? You can also link to our free tools.